
LFISuite
Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

Windows local privilege escalation exploit for CVE-2018-8120 supporting x32 and x64 architectures, tested on multiple Windows 7 and 2008 variants.

PowerShell script for local privilege escalation via PrintNightmare (CVE-2021-34527). Injects a custom DLL payload to add a local admin user,…

Windows active user credential phishing tool

BurpSuite extension that converts HTTP requests into JavaScript XMLHttpRequest code for streamlined XSS proof-of-concept generation and web…

Python exploit for CVE-2023-30547 vm2 sandbox escape vulnerability. Generates base64-encoded JSON payload to open a reverse shell from vulnerable…

The all-in-one browser extension for offensive security professionals 🛠

The ultimate WinRM shell for hacking/pentesting

Web-based reverse shell generator supporting multiple payload formats, encoding, listener integration, and raw download mode for penetration testing…

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Deserialization payload generator for a variety of .NET formatters

A Windows reverse shell payload generator and handler that abuses the http(s) protocol to establish a beacon-like reverse shell.

This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

🔥 CHAOS is a free and open-source Remote Administration Tool that allow generate binaries to control remote operating systems.

JNDI注入测试工具(A tool which generates JNDI links can start several servers to exploit JNDI Injection vulnerability,like Jackson,Fastjson,etc)

Automated exploitation tool for JBoss, Java deserialization, and Struts2 vulnerabilities with built-in scanning, payload generation, and reverse…

High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

Web-based XSS exploitation toolkit with modules for encoding/decoding payloads, generating JavaScript probes, and automating cross-site scripting…